Identity

Claro + SCIM Provisioning

Stop managing Claro users by hand. Let your identity provider create, update, and deactivate accounts for you.

Overview

Claro supports SCIM 2.0, an open standard for automated user lifecycle management, so accounts and groups in Claro stay synchronized with your identity provider without manual CSV imports or ad hoc admin work. When someone joins, moves teams, or leaves the organization in your directory, the same change propagates to Claro, keeping the simulation and training population accurate.

This matters most for organizations with frequent headcount changes or strict offboarding requirements: when an employee is deactivated in the identity provider, SCIM ensures they lose access to Claro as well, without waiting on a manual step. That removes a common gap where former employees linger in a training platform long after they have left.

SCIM covers groups as well as individual users. Group membership changes in your identity provider are reflected in Claro, which is what lets you drive targeting and assignment logic off the same organizational structure your directory already maintains, rather than rebuilding it by hand. Departments and teams stay consistent between systems, so simulations and training reach exactly the right people.

Provisioning is authenticated with a SCIM bearer token generated in Claro and registered in your identity provider, so the connection is scoped and revocable. SCIM does not force an all-or-nothing model either: where it is in use, those accounts are managed automatically, while admins can still manage other users manually. For audit and data-protection purposes, deactivation follows your identity provider's signal, and historical training and simulation data is retained per your configured retention settings. In practice, SCIM pairs naturally with SAML single sign-on: SAML decides who can authenticate at any given moment, while SCIM keeps the underlying account population, attributes, and group membership correct over time, so the two together make your identity provider the single source of truth for both access and lifecycle in Claro.

How it works

  • Generate a SCIM token

    Create a SCIM bearer token in Claro's admin settings and register Claro as a SCIM application in your identity provider to authenticate the connection.

  • Configure the sync

    Point your identity provider at Claro's SCIM endpoint and select which users and groups to provision into the platform.

  • Provision users and groups

    Your identity provider creates Claro accounts and groups from the assigned population, so the training list matches your directory from day one.

  • Changes sync automatically

    User creation, attribute updates, group membership changes, and deactivations in your identity provider are pushed to Claro automatically as they happen.

  • Deactivation removes access

    When someone is deactivated in your directory, SCIM deactivates their Claro account too, while historical data is retained per your retention settings.

Frequently asked questions

  • For provisioned users, yes; you no longer need to create or edit those accounts by hand in Claro. Admins can still manage users manually where SCIM is not in use.

Not sure how Claro fits your stack?

Tell us what you run today and we will walk you through the integration path.

Request a demo